PT-2005-4022 · Aenovo · Aenovo+2
Devil_Box
+2
·
Published
2005-10-14
·
Updated
2017-07-11
·
CVE-2005-3208
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aeNovo (affected versions not specified)
aeNovoShop (affected versions not specified)
aeNovoWYSI (affected versions not specified)
Description
The issue allows remote attackers to execute arbitrary SQL code, potentially enabling cross-site scripting (XSS) attacks in resulting error messages. This can be achieved via the
password parameter in "control.asp" and the strSQL parameter in "search.asp".Recommendations
For aeNovo, consider restricting access to the
control.asp and search.asp pages until a fix is available.
For aeNovoShop, avoid using the password parameter in "control.asp" and the strSQL parameter in "search.asp" until the issue is resolved.
For aeNovoWYSI, as a temporary workaround, consider disabling the execution of SQL code from user-input parameters in "control.asp" and "search.asp" until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aenovo
Aenovoshop
Aenovowysi